The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… (CVE-2026-93908)
The Real Estate Manager plugin for WordPress suffers from a stored cross-site scripting (XSS) vulnerability via the 'before_price_text' parameter in all versions up to and including 7.3. Authenticated users with subscriber-level access or higher can inject malicious scripts that execute when other users view the affected pages. This vulnerability arises due to insufficient input sanitization and output escaping, lack of capability, nonce, or ownership checks on the AJAX handler, and the use of update_post_meta which bypasses typical filtering mechanisms.
AI Analysis
Technical Summary
CVE-2026-93908 describes a stored XSS vulnerability in the Real Estate Manager – Property Listing and Agent Management WordPress plugin. The flaw exists in the 'before_price_text' parameter, which is insufficiently sanitized and escaped, allowing authenticated attackers with subscriber-level privileges or higher to inject arbitrary JavaScript. The vulnerability is exacerbated by the absence of capability checks, nonce verification, or ownership validation in the wp_ajax_rem_create_pro_ajax handler. Additionally, because the injected data is stored via update_post_meta rather than post_content, WordPress's wp_kses filtering tied to the unfiltered_html capability does not apply, enabling persistent script injection.
Potential Impact
An attacker with subscriber-level or higher access can inject malicious scripts that execute in the context of other users viewing the affected pages, potentially leading to session hijacking, privilege escalation, or other malicious actions. The vulnerability does not require user interaction (no UI needed) and affects confidentiality and integrity but not availability. There are no known exploits in the wild at this time.
Mitigation Recommendations
No patch or official fix is currently documented. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict subscriber-level users from untrusted sources and monitor for suspicious activity related to the 'before_price_text' parameter. Avoid granting unnecessary privileges to users and consider disabling or limiting the use of the vulnerable AJAX handler if possible.
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… (CVE-2026-93908)
Description
The Real Estate Manager plugin for WordPress suffers from a stored cross-site scripting (XSS) vulnerability via the 'before_price_text' parameter in all versions up to and including 7.3. Authenticated users with subscriber-level access or higher can inject malicious scripts that execute when other users view the affected pages. This vulnerability arises due to insufficient input sanitization and output escaping, lack of capability, nonce, or ownership checks on the AJAX handler, and the use of update_post_meta which bypasses typical filtering mechanisms.
CVSS v3.1
Score 6.4medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-93908 describes a stored XSS vulnerability in the Real Estate Manager – Property Listing and Agent Management WordPress plugin. The flaw exists in the 'before_price_text' parameter, which is insufficiently sanitized and escaped, allowing authenticated attackers with subscriber-level privileges or higher to inject arbitrary JavaScript. The vulnerability is exacerbated by the absence of capability checks, nonce verification, or ownership validation in the wp_ajax_rem_create_pro_ajax handler. Additionally, because the injected data is stored via update_post_meta rather than post_content, WordPress's wp_kses filtering tied to the unfiltered_html capability does not apply, enabling persistent script injection.
Potential Impact
An attacker with subscriber-level or higher access can inject malicious scripts that execute in the context of other users viewing the affected pages, potentially leading to session hijacking, privilege escalation, or other malicious actions. The vulnerability does not require user interaction (no UI needed) and affects confidentiality and integrity but not availability. There are no known exploits in the wild at this time.
Mitigation Recommendations
No patch or official fix is currently documented. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict subscriber-level users from untrusted sources and monitor for suspicious activity related to the 'before_price_text' parameter. Avoid granting unnecessary privileges to users and consider disabling or limiting the use of the vulnerable AJAX handler if possible.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-jm7p-f6m7-xr3m
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-93908"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abd30852a4e24523d3401eb
Added to database: 09/30/2026, 15:53:41 UTC
Last enriched: 09/30/2026, 16:08:51 UTC
Last updated: 10/01/2026, 05:08:55 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.